PT-2025-27257 · Code Projects · Code-Projects Food Distributor Site
Liyu
·
Published
2025-06-27
·
Updated
2025-07-11
·
CVE-2025-6777
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
code-projects Food Distributor Site version 1.0
Description:
A critical issue has been found in the processing of the file /admin/process login.php. The manipulation of the
username and password arguments leads to SQL injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Recommendations:
For code-projects Food Distributor Site version 1.0, consider disabling the
/admin/process login.php file until a patch is available. Restrict access to this file to minimize the risk of exploitation. Avoid using the username and password arguments in the affected API endpoint until the issue is resolved.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Code-Projects Food Distributor Site